Explanation
Threat actors are using a phishing campaign that mimics the appearance of the official Luxembourgish government website (https://gouvernement.lu/fr.html).
The attack begins with a fake SMS (in some cases also with a fake e-mail) asking to pay a fee of 49 euros.
The SMS text reads as follows:
Info Guichet : Vous avez une contravention impayée d'un montant de 49€ à ce jour. Consultez votre dossier d'infraction via : https://public-guichet.lu
from: +33 6 22 51 10 23
Please note the order of the words and the use of - instead of . in the link https://public-guichet.lu. The original link is https://guichet.public.lu/fr.html
When clicking on the link (“https://public-guichet.lu), the user is first presented a fake form which asks for a verification code.
Once that information is provided, the victim is redirected to a card form. After which the victim is redirected to another fake form. This form asks for
personal information.
Finally, a page is shown that the payment was “successful” to make the user believe that he was indeed interacting with guichet.lu.
Example